Multiple XSS Vulnerabilities in JetBrains YouTrack Due to Insecure Markdown Parsing
CVE-2024-50580
5.4MEDIUM
What is CVE-2024-50580?
Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in JetBrains YouTrack due to insecure handling of markdown parsing and custom rendering rules. These flaws can allow an attacker to execute arbitrary scripts in the context of a user's session, potentially leading to data theft and other security breaches. It is imperative for users to exercise caution and implement necessary security measures to mitigate these risks.